Skip to content
Legal

Privacy Policy

What data ORGanizer for Salesforce handles, where it is stored, and who can read it. Written for the extension as it actually behaves, not as a template.

Last updated: September 21, 2026 · Applies to: ORGanizer for Salesforce version 1.0 and this website.

The short version

  • Your Salesforce credentials never reach us. They are stored in your own browser and, if you turn encryption on, encrypted there with a key derived from a password only you know.
  • The extension talks to your Salesforce ORGs directly. Queries, describes, Apex, Health Monitor and Access Lens data all go from your browser to your ORG and back. None of it passes through our servers.
  • We do not sell, rent or share personal data with third parties for their own purposes.
  • The only routine call to our servers is licence validation, and only when you apply or refresh a licence code.
  • The extension does not send usage analytics. This website does — see This website.
  • Sponsor banner clicks pass through this website. Clicking a banner opens a link on organizer.solutions, which counts the click and forwards you to the sponsor — see Sponsor banners. Nothing is sent while a banner is merely on screen.

Who we are

ORGanizer for Salesforce and this website are operated by Enrico Murru (“we”, “us”).

For the data the extension keeps in your browser and the data it reads from your Salesforce ORGs, we are not a controller or a processor: that data never reaches us. Where you use the extension against an employer's Salesforce ORG, your employer remains the controller of the ORG data you access through it.

The browser extension

Everything the extension stores lives in your browser's own extension storage (chrome.storage.local, and chrome.storage.sync for the items you explicitly mark as synced). Nothing is uploaded to us.

WhatWhereEncrypted
Salesforce logins — label, group, username, password, security token, login URL, landing page and options Local; also synced for the logins you mark as synced Passwords and tokens, if you enable encryption
OAuth refresh tokens, for logins configured to use OAuth Local only — never synced Yes, with a key tied to your extension installation
ORG configurations — ORG Id, My Domain, tab label and colour Local and synced Not applicable (no secrets)
Quick links — labels, paths, ORG scope Local and synced Not applicable
Quick link history, V.I.Q. and V.I.S. (saved queries and scripts) Local only Not applicable
Settings — enabled features, shortcuts, API version, ORGanizer button position Local and synced Not applicable
Automatic backups of your logins and ORG configurations Local only, capped at the number you choose Same as the data they contain
Error and debug logs, when you enable the debug log Local only. Sent to us only if you download and attach them to a support request No
Licence state — licence type, applied promo codes, the email address you entered when applying a code, an installation identifier, an API call counter Local; licence type also synced Obfuscated
Cached ORG describes and session data used while a tab is open Browser session storage, cleared when the browser closes Not applicable

Salesforce sessions

The extension reads the Salesforce session cookies of the ORGs you are logged into, on the domains you have granted it (see Browser permissions). This is how it knows which ORGs are open, colours their tabs, and calls the Salesforce API on your behalf. Session identifiers are used in the browser and are never transmitted to us.

Data read from your Salesforce ORGs

Tools such as the Quick Console, Health Monitor and Access Lens query your ORGs through the Salesforce APIs, using your own session and therefore your own permissions. The results are rendered in your browser and held in memory for as long as the page is open. The Health Monitor keeps no cache. Anything you export — CSV, JSON, a ZIP report — is written by your browser to your own device. None of this data is sent to us.

Encryption

Encryption is optional and off until you turn it on. When it is on, each stored password and security token is encrypted individually with AES-GCM (256-bit) using a key derived from your master password with PBKDF2-SHA256 over 600,000 iterations and a random per-installation salt, through the browser's Web Crypto API.

The derived key is held only in the memory of the extension's background worker. It is never written to disk and never transmitted. When the browser closes, the extension reloads or the worker goes idle, the key is gone and you are asked for your master password again. Your master password itself is never stored: what is stored is a one-way verifier that can confirm a password is correct without revealing it.

We cannot recover your master password or your data. There is no reset, no backdoor and no recovery service. If you lose it, the encrypted credentials are unrecoverable and the only way forward is a hard reset, which erases them.

With encryption off, passwords and tokens are stored obfuscated but not cryptographically protected. Anyone with access to your browser profile can read them. We strongly recommend turning encryption on.

Browser sync

If you mark a login as synced, it is placed in your browser's sync storage. From there, your browser vendor — Google for Chrome, Microsoft for Edge, Mozilla for Firefox — replicates it to your other signed-in browser profiles, under their privacy policy and their infrastructure, not ours. We never see it.

Data placed in sync storage is encrypted by ORGanizer beforehand if you enabled encryption. If you would rather nothing left your device, leave logins unsynced; ORG configurations are always synced and contain no secrets.

What leaves your browser

DestinationWhenWhat is sent
Your Salesforce ORGs
*.salesforce.com, *.force.com and related domains
Whenever you use a feature that reads from an ORG Your own session identifier and the API request. Direct browser-to-Salesforce; we are not in the path.
api.organizer.solutions When you apply a licence or promo code, and when the extension periodically re-validates it The licence code, the email address you typed when applying it, an anonymous installation identifier, the client name you set, the product identifier, the extension id and version. No Salesforce data, no credentials.
organizer.solutions
this website
When the popup loads its message panel or you open a link to the site An ordinary web request to a public, read-only endpoint. No credentials, no ORG data.
organizer.solutions
sponsor banner links
Only when you click a sponsor banner Which banner you clicked and where in the interface you clicked it, your anonymous installation identifier, the extension id and version, your browser and your licence tier. No email address, no licence code, no ORG data, and nothing about the page you were on. See Sponsor banners.
api.status.salesforce.com Only when you run the Health Monitor's instance status section The instance name of the ORG being analysed. Salesforce's own public status service.

That is the complete list. The extension contacts no advertising network, no analytics endpoint and no third-party service beyond the above.

Sponsor banners

ORGanizer is free because sponsors pay for it, and the extension shows their banners on the free licence. Clicking one is the single moment where the extension and this website meet, so it is worth being exact about what happens.

A banner click opens a link on organizer.solutions, which records the click and forwards you to the sponsor. Nothing is sent while a banner is merely on screen — there is no background request, no beacon and no impression counter. No click, no record.

What that link carries:

  • which banner you clicked, and where in the interface you clicked it;
  • your anonymous installation identifier — the same one described in What leaves your browser, not a new one created for this;
  • the extension id and version, your browser family, and your licence tier.

What it does not carry: your email address, your licence code, anything about your Salesforce ORGs, and nothing about the page you were on when you clicked. Banners shown inside a Salesforce page are built so that the address of that page is not sent to us either.

We keep that as a click record — without your IP address and without your user agent — and count it. The purpose is to know which sponsors and which placements are worth keeping, and to be able to tell a sponsor honestly how many clicks they received. The same click also produces a banner_click event in Google Analytics, as any other page of this site would; the installation identifier is deliberately not part of what goes to Google.

Legal basis (GDPR). Our legitimate interest in measuring the sponsorships that pay for the extension. If you would rather not be counted, do not click the banners — and a PRO licence removes them altogether.

Browser permissions

From version 1.0, the extension is installed with no access to any Salesforce domain. It asks for the domains of an ORG the first time you open that ORG, one ORG at a time, and you can review and revoke every grant in Options → Permissions.

The permissions granted at install time are limited to what the extension needs to function — tabs, cookies, storage, scripting, downloads and alarms — and are documented individually in the documentation. The extension does not request access to your browsing history, your Google identity or your email address anymore.

This website

The website (organizer.solutions) is separate from the extension and does use third-party services:

Google Analytics

Aggregate visit statistics: pages viewed, approximate location, browser and device type. Set through cookies, which the consent banner lets you refuse.

Google AdSense

Advertising on some pages. Google may use cookies and identifiers to select ads; you can control this at Google Ad Settings and opt out of personalised advertising at the NAI opt-out page.

Embedded content

YouTube videos on the Guides page, Google Forms on the survey page, Gumroad on the subscribe page, and support forms served from a Salesforce site. Each sets its own cookies under its own privacy policy once loaded.

Sponsor banner clicks

A click on a sponsor banner, in the extension or on this site, passes through a redirect page that counts it and sends a banner_click event to Google Analytics. Sponsor banners lists exactly what is recorded.

Server logs

Standard web-server records — IP address, timestamp, requested URL, user agent — kept for security and troubleshooting.

Session cookie

A short-lived cookie used only where the site needs to carry state between two requests, such as the news redirect page and the administrative pages.

Legal basis (GDPR). Analytics and advertising cookies rely on your consent, given through the banner and withdrawable at any time by clearing the site's cookies. Server logs and the session cookie rely on our legitimate interest in operating the site securely, and sponsor banner click records on our legitimate interest in measuring the sponsorships that fund the extension.

Do Not Track. There is no agreed standard for honouring DNT signals across the third-party services above; we do not make a claim we cannot keep. Refusing cookies in the banner, or blocking them in your browser, is the effective control.

Payments and licensing

Licences are sold through Gumroad, which acts as merchant of record. Your payment details are collected and processed by Gumroad under their privacy policy; we never see your card details. From Gumroad we receive the information needed to issue and validate a licence: the purchaser's email address, the product bought and the licence status.

When you apply a licence code in the extension, our licensing API receives the data listed in What leaves your browser and returns whether the licence is valid. We keep the licence record, the associated email address and, for bulk licences, the child codes issued and the email addresses they were assigned to, for as long as the licence is active.

Support requests

When you use the support form, we receive what you put in it: your name, your email address, the description of the problem and any file you attach. We use it to answer you and to fix the problem, and for nothing else.

Check your attachments. An exported backup file contains your Salesforce credentials in the clear, and a debug log can contain ORG identifiers and query text. Never attach either unless you have removed what you do not want us to see.

Subscribing to release announcements passes your email address to Gumroad, which sends them. Every message carries an unsubscribe link.

Retention and deletion

  • In your browser: data stays until you delete it. Removing a login, deleting an ORG, or running Hard reset in Options → Advanced erases it. Uninstalling the extension removes its local storage; sync storage is cleared by your browser vendor according to their rules.
  • Licence records: kept for as long as the licence is active.
  • Support correspondence: kept while the issue is open and for a reasonable period afterwards to handle follow-ups.
  • Website server logs: kept for a short operational period, then rotated out.
  • Sponsor banner click records: kept for 24 months, then deleted.

Your rights

If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent at any time. Write to [email protected] and we will respond within one month.

If you are a California resident, you may request the categories and specific pieces of personal information we have collected, request deletion, and not be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising beyond the advertising cookies described in This website, which the consent banner controls.

Note that we cannot act on a request concerning data held only in your own browser or in your Salesforce ORG: we have no access to it. Those are yours to delete directly.

Children

ORGanizer for Salesforce is a professional tool for Salesforce administrators and developers. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to [email protected] and we will delete it.

Changes to this policy

We update this policy when the product changes. The date at the top always reflects the current version, and material changes are announced through the extension's message panel and the change log. Continuing to use ORGanizer after a change means you accept the updated policy.

Contact

Questions about this policy, or about your data: the support form, or [email protected].

See also the End User License Agreement and the Security Statement.